CVE-2024-46613: Weechat

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

WeeChat before 4.4.2 has an integer overflow and resultant buffer overflow at core/core-string.c when there are more than two billion items in a list. This affects string_free_split_shared , string_free_split, string_free_split_command, and string_free_split_tags.

Affected products

  • Weechat Weechat: from 0.1.6, before 4.4.2 (fixed in 4.4.2)

Published 2024-11-10. Last modified 2026-06-17.